CVE-2023-46916
MEDIUMCVSS 4.3/10EPSS 0.51%
Last modified
CVE-2023-46916 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Maximawatches | Maxima Max Pro Power Firmware | 1.0_486a |
References
- http://packetstormsecurity.com/files/175660Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/175660Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-46916?
Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.
How severe is CVE-2023-46916?
CVE-2023-46916 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 0.51% probability of exploitation in the next 30 days.
How do I fix CVE-2023-46916?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-46894An issue discovered in esptool 4.6.2 allows attackers to vie…7.5
- CVE-2023-4690The Elementor Addon Elements plugin for WordPress is vulnera…4.3
- CVE-2023-46906juzaweb <= 3.4 is vulnerable to Incorrect Access Control, re…4.9
- CVE-2023-4691The WordPress Online Booking and Scheduling Plugin WordPress…7.2
- CVE-2023-46911There is a Cross Site Scripting (XSS) vulnerability in the c…6.1
- CVE-2023-46914SQL Injection vulnerability in RM bookingcalendar module for…9.8
- CVE-2023-46918Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PL…4.6
- CVE-2023-46919Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 an…6.3
- CVE-2023-4692An out-of-bounds write flaw was found in grub2's NTFS filesy…7.8
- CVE-2023-46925Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS)…4.8
- CVE-2023-46927GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer…5.5
- CVE-2023-46928GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpa…5.5
Are you affected by CVE-2023-46916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
